Expirovaný certifikát = výpadek. Špatně spravované certifikáty jsou časovaná bomba.
cert-manager v Kubernetes¶
Instalace¶
helm install cert-manager jetstack/cert-manager –set installCRDs=true
Let’s Encrypt issuer¶
apiVersion: cert-manager.io/v1 kind: ClusterIssuer metadata: name: letsencrypt spec: acme: server: https://acme-v02.api.letsencrypt.org/directory email: [email protected] privateKeySecretRef: name: letsencrypt-key solvers: - http01: ingress: class: nginx
Monitoring¶
Prometheus alert¶
- alert: CertificateExpiringSoon expr: certmanager_certificate_expiration_timestamp_seconds - time() < 7 * 24 * 3600 labels: severity: warning annotations: summary: “Certificate {{ $labels.name }} expires in less than 7 days”
Klíčový takeaway¶
cert-manager pro K8s, Prometheus pro monitoring. Automatizujte obnovu, monitorujte expiraci.
securitycertificatestlscert-manager